Live data from Hacker News

Even Akamai screws up their SSL certs

akamai.com

11–20 of 36 posts

Re: Even Akamai screws up their SSL certs

#11
This happens with almost any Akamai'zed domain, if you drop https:// in front of it you get the shared Akamai cert. Customers that pay for SSL get their own pool of IPs that respond with only their cert.

Same thing happens with any shared web host that happens to listen on SSL.

Re: Even Akamai screws up their SSL certs

#12
post #11

This happens with almost any Akamai'zed domain, if you drop https:// in front of it you get the shared Akamai cert. Customers that pay for SSL get their own pool of IPs that respond with only their cert. Same thing happens with any shared web host that happens to listen on SSL.

[deleted]

Re: Even Akamai screws up their SSL certs

#15
post #6
post #5

Earlier quoted context omitted.

> Of course it would be nice if everything were HTTPS... Nice try, Certificate Authorities!

>> Of course it would be nice if everything were HTTPS... > Nice try, Certificate Authorities! Nice try, NSA.

>>> Of course it would be nice if everything were HTTPS...

>> Nice try, Certificate Authorities!

> Nice try, NSA.

Nice try, HN.

Re: Even Akamai screws up their SSL certs

#16

Only partly related: Most websites don't get proper certificates for their FQDN -- even Google [1]. That, to me, is screwed up. [1] https://www.google.com./

I don't think it's possible to buy a certificate with a dot at the end, so I don't see how this is Google's problem.

It seems to be either a problem with Firefox or with the domain name system in general.

It looks like the problem should be fixed in 2016 because then all non-FQDN certificates will have expired. Then browsers can go ahead and assume that google.com. in a url is the same as google.com in a certificate.

Re: Even Akamai screws up their SSL certs

#17

Better yet, where they absolutely mean to use HTTPS they sometimes use weak keys and ciphers and get an "F" from the Qualys SSL Labs tool. Blogs.akamai.com isn't the only place this happens: https://www.ssllabs.com/ssltest/analyze.html?d=blogs.akamai....

Someone's parents are going to be really mad about this report card:

https://www.ssllabs.com/ssltest/analyze.html?d=developer.aka...

https://www.ssllabs.com/ssltest/analyze.html?d=a248.e.akamai...

https://www.ssllabs.com/ssltest/analyze.html?d=network.akama...

The thing is, the worst part is knowing a child is capable of A's:

https://www.ssllabs.com/ssltest/analyze.html?d=control.akama...

Re: Even Akamai screws up their SSL certs

#18

Better yet, where they absolutely mean to use HTTPS they sometimes use weak keys and ciphers and get an "F" from the Qualys SSL Labs tool. Blogs.akamai.com isn't the only place this happens: https://www.ssllabs.com/ssltest/analyze.html?d=blogs.akamai....

Not the biggest crisis. Okay, they have several awful cipher suites enabled, but no sane client would ever use them. The client report shows that almost every client uses AES; a couple crappy ones use RC4 or 3DES.

They don't have PFS, either. That's bad, though unfortunately still common. As far as I know Akamai's position is that the (small) performance cost of PFS is unacceptable. They would be delighted if it was faster (which people are working on).

I think the F is because of the 1024-bit, MD5 CA. That seems to be more of an argument for clients to disable that CA certificate, especially since there's another, good trust path, but maybe I'm missing something.

Re: Even Akamai screws up their SSL certs

#20
post #6

Earlier quoted context omitted.

>> Of course it would be nice if everything were HTTPS... > Nice try, Certificate Authorities! Nice try, NSA.

>>> Of course it would be nice if everything were HTTPS... >> Nice try, Certificate Authorities! > Nice try, NSA. Nice try, HN.

Nice try... wait, this is not on reddit. Let's stop the joke now.
Post reply on HN